use cases

Smarter onboarding for Google Workspace and Microsoft 365 integrations

Pre-select the Google or Microsoft connector at signup, pre-fill admin consent with the tenant ID, and catch personal accounts before onboarding stalls.

This is the problem isBusinessEmail was built for. A user signs up, reaches “Connect your workspace”, and only then discovers that their @gmail.com or @outlook.com account can’t do what your integration needs. Onboarding stalls, a support ticket follows. Our story.

What personal accounts can’t do

You need Requires Personal account?
Google Workspace Admin SDK, domain-wide delegation A Workspace organization and its admin No: personal Gmail has no admin console
Shared Drives A Workspace organization No
Microsoft Graph admin consent / application permissions An Entra ID tenant and an admin No: personal Microsoft accounts can’t grant org-wide consent
SharePoint Online, OneDrive for Business, Teams org data A Microsoft 365 tenant No

Use the signal at three moments

1. At signup: set expectations

If the product needs a tenant and the email is personal, say so right away: “To connect SharePoint you’ll need your work Microsoft account.” Then let them continue with a work email or explore read-only.

2. On the connect screen: pre-select the right connector

const v = await checkEmail(user.email); // stored at signup; don't re-check every time

const ms = v.workspace?.microsoft_365;
const google = v.workspace?.google_workspace;

let suggested = null;
if (ms?.detected && !google?.detected) suggested = 'microsoft';
else if (google?.detected && !ms?.detected) suggested = 'google';
// both detected: show both, Microsoft first if mail is on Exchange (reason mx_microsoft_365)

Show the suggested connector first and the other one below it. Don’t hide options: detection is a hint.

With a tenant ID you can send an admin straight to the consent screen for their tenant:

const url = new URL(`https://login.microsoftonline.com/${ms.tenant_id}/v2.0/adminconsent`);
url.searchParams.set('client_id', process.env.MS_CLIENT_ID);
url.searchParams.set('scope', 'https://graph.microsoft.com/.default');
url.searchParams.set('redirect_uri', 'https://app.example.com/integrations/microsoft/callback');
url.searchParams.set('state', csrfToken);

For Google sign-in, the hd parameter hints the expected Workspace domain, and Microsoft supports domain_hint / login_hint to skip account pickers.

Federated tenants

If auth is federated with an identity_provider such as Okta, the admin who can consent is often in IT. Offer “Send this link to your admin” from the start, with the pre-filled consent URL.

What detection can’t tell you

  • Whether this user is an admin, or will get consent.
  • Whether they have a license for the product you integrate with.
  • Whether IT policies block third-party apps.

Design for “invite your admin” anyway; detection makes the right path the default.

Try it

Related: Workspace detection · Microsoft 365 tenant vs Outlook.com